← Back
CWE-400

3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,613)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pngdec Project
1Pngdec
Jun 17, 2026
Aug 16, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.
2Fedoraproject
Varnish Cache Project
2Fedora
Varnish Cache
Jun 17, 2026
Aug 11, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backe...Show more
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.Show less
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Azure Site Recovery Denial of Service Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
1F Secure
8Atlant
Cloud Protection For SalesforceElements Collaboration Protection+5 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be trigge...Show more
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.Show less
1Redhat
3Integration Camel K
Jboss FuseUndertow
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/prox...Show more
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in that a front-end proxy marking the backend worker (application server) as an error state and not forward requests to the worker for a while. In mod_cluster, this continues until the next STATUS request (10 seconds intervals) from the application server updates the server state. So, in the worst case, it can result in "All workers are in error state" and mod_cluster responds "503 Service Unavailable" for a while (up to 10 seconds). In mod_proxy_balancer, it does not forward requests to the worker until the "retry" timeout passes. However, luckily, mod_proxy_balancer has "forcerecovery" setting (On by default; this parameter can force the immediate recovery of all workers without considering the retry parameter of the workers if all workers of a balancer are in error state.). So, unlike mod_cluster, mod_proxy_balancer does not result in responding "503 Service Unavailable". An attacker could use this behavior to send a malicious request and trigger server errors, resulting in DoS (denial of service). This flaw was fixed in Undertow 2.2.19.Final, Undertow 2.3.0.Alpha2.Show less
1F5
1Nginx Instance Manager
Jun 17, 2026
Aug 4, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Tech...Show more
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Aug 4, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilizati...Show more
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1F5
2Big Ip Access Policy Manager
Big Ip Ssl Orchestrator
Jun 17, 2026
Aug 4, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an i...Show more
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1V8n Project
1V8n
Jun 17, 2026
Aug 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service...Show more
v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload of 'a' + 'a'.repeat(i) + 'A' with 32 leading characters took 29443 ms to execute. The same issue happens with uppercase(). Users are advised to upgrade. There are no known workarounds for this issue.Show less
2Fedoraproject
Rust Websocket Project
2Fedora
Rust Websocket
Jun 17, 2026
Aug 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the i...Show more
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would allocate a buffer based on the declared dataframe size, which may come from an untrusted source. When `Vec::with_capacity` fails to allocate, the default Rust allocator will abort the current process, killing all threads. This affects only sync (non-Tokio) implementation. Async version also does not limit memory, but does not use `with_capacity`, so DoS can happen only when bytes for oversized dataframe or message actually got delivered by the attacker. The crashes are fixed in version 0.26.5 by imposing default dataframe size limits. Affected users are advised to update to this version. Users unable to upgrade are advised to filter websocket traffic externally or to only accept trusted traffic.Show less
1Openzeppelin
4Contracts
Contracts UpgradeableOpenzeppelin Eth+1 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally...Show more
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Juniper Project
1Juniper
Jun 17, 2026
Aug 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upg...Show more
Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upgrade. Users unable to upgrade should limit the recursion depth manually.Show less
1Ovarro
8Tbox Lt2 530 Firmware
Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 more
Jun 17, 2026
Jul 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
1Apache
1Mxnet
Jun 17, 2026
Jul 24, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a speciall...Show more
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular expression evaluation to use excessive resources to attempt a match. This issue affects Apache MXNet versions prior to 1.9.1.Show less
1H96tvbox
1H96 Pro Plus Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
1Pexip
1Pexip Infinity
Jun 17, 2026
Jul 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.
1Mattermost
1Mattermost
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Sla...Show more
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.Show less
1Linuxfoundation
1Kubeedge
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient...Show more
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory which could allow an attacker to send a request that returns a response with a large body. The consequence of the exhaustion is that the process which invokes a WSClient will be in a denial of service. The software is affected If users who are authenticated to the edge side connect to `cloudhub` from the edge side through WebSocket protocol. This bug has been fixed in Kubeedge 1.11.1, 1.10.2, and 1.9.4. There are currently no known workarounds.Show less